Nebius is a Nasdaq-listed tech company that aims to become one of the world’s leading AI infrastructure providers. Headquartered in Amsterdam, we have R&D and commercial hubs across the US, Europe and Israel.
We build full-stack AI infrastructure to service the explosive growth of the global AI industry, including large-scale GPU clusters, cloud platforms and tools and services for developers. Our 500 employees include around 400 highly skilled engineers with a proven track record of developing world-class hardware and software solutions across cloud and AI/ML.
We are rapidly growing our infrastructure network with an ambitious investment program to build out data centers and colocations in the US and Europe. A Reference Platform NVIDIA Cloud Partner, Nebius’ AI-native cloud platform provides high-end infrastructure and tools for training, fine-tuning and inference.
Nebius is growing fast, and we’re always looking for the best talent to join our company. Along with highly competitive compensation and extensive opportunities for professional development, we offer a dynamic work environment where innovation, creativity and teamwork are highly prized and open up exciting new opportunities. As an equal opportunity employer, we are committed to fostering a diverse and inclusive workplace, where all applicants are given fair consideration and every team member is empowered to contribute to their fullest potential.
The Security Engineering Team within the Platform Security organization is responsible for the strategic selection, implementation, management, and optimization of cybersecurity tools and technologies that improve security capabilities of the organization's platform. This team is instrumental in fortifying the security posture, proactively identifying and responding to security threats, ensuring the resilience and protection of critical data, systems, and services.
We are looking for an Application Security Engineer who will ensure the security of our software by identifying and mitigating vulnerabilities, implementing best security practices, and collaborating with development teams. The ideal candidate will have a strong background in secure coding, vulnerability assessment, and penetration testing.
Build and maintain ASPM tools and their rules.
Identify, analyze, and remediate application security vulnerabilities using tools like ASPM.
Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC).
Conduct manual and automated penetration testing of applications.
Develop and maintain secure coding guidelines for development teams.
Facilitate threat modeling and risk assessments on new and existing applications.
Stay updated on the latest security threats, vulnerabilities, and mitigation techniques.
Serve as an application security subject matter expert to other teams.
4+ years of experience in application security.
Strong knowledge of common application security risks (e.g. OWASP Top 10) and how to mitigate them.
Experience with secure coding practices in languages such as Python, Go, Java, or JavaScript.
Proficiency in a common programming language (such as Go or Python) with a willingness to learn Go, if necessary.
Hands-on experience with security testing tools (Burp Suite, ZAP, Semgrep, etc.).
Understanding of authentication protocols like SAML or OIDC.
Experience in conducting threat-modeling sessions.
Strong problem-solving and analytical skills.
Good written and verbal communication skills in English.
Willingness to learn new things.
Being comfortable working independently.
Confidence in presenting your ideas and opinions in a manner that can be challenged, while responding well to feedback.
Experience in designing, building, and maintaining security automation.
Experience in translating compliance and regulation requirements into technical specifications.
Experience in exploiting vulnerabilities in web applications, Linux kernels, containers, and networks.
Security certifications such as OSCP or OSWE.
What we offer
We’re growing and expanding our products every day. If you’re up to the challenge and are excited about AI and ML as much as we are, join us!